Results 1 to 10 of 19

Thread: EMERGENCY!! 20 RED files HELP PLZ

Hybrid View

  1. #1
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Look, I really am trying to be patient here. For now I have no idea what programs you originally removed, what file alterations you have done, what programs or services you have stopped or disabled, or what programs were originally installed.

    I know absolutely nothing about the original set up of this only two week old computer.
    You say you have removed unnecessary items, but you have no way of proving to me that these were unnecessary and I do not have the names of any of them. Or why, other than your personal opinion, that they were the unnecessary or why you felt these would have affected the internet connections. Unless they were actually running at the times of disconnect they would not even be considered as part of the problem.

    You have installed and excellent anti-virus program, Avira, one of the highest ranked programs and I applaud you for that.

    However, you have installed one of the poorest ranked Firewalls around today, Zone Alarm. The built in Windows Firewall gets higher rankings than Zone Alarm does on most tests. And since the disconnect problems have continued the problem obviously was not the Windows Firewall.

    Yet you want me to make a determination without having any information whatsoever. You ran an old version of a program that clearly was not compatible with or meant to be run on Vista or Windows 7. You have made what you feel were correct decisions based on the use of a program that was not compatible with the system using a 5 year old HJT parser which was never, ever meant to be used with any other version of HiJackThis except version 1.99.1 OR with any other operating system newer than XP.
    You post a new log using the current version of HJT which was great...but, one hour later you post a new log with the message that you have removed more programs, and also a registry editor.

    Registry editor? This is absolutely positively something we do not recommend and I have no idea what other programs you felt necessary to remove. There was absolutely nothing on that uninstall list, except for that uTorrent program which I would have declared absolutely, positively needed to be removed or would have had any effect whatsoever concerning the loss of internet service.

    Me= 30 years of working on comps from netbooks to mainframes...when I send someone to your HJT online parser, I expect it to be up to date, as well as the stickies at the top of this forum.

    I realize this is all a free service, lately subsumed by Trend Micro, maybe a phone call is in order, if the online parser is also out of date.
    The acquisition of HiJackThis by Trend Micro is NOT recent. This happened over 3 years ago so if you were truly up to date on this program you would know this. The LAST version created and released in February 2005 by Merijn Bellekom was version 1.99.1. Mr. Bellekom joined the Malwarebytes.org development team in January of 2010.

    For you to say you "expect" stickies to be up to date, well all I can say is we try the best we can. The Read Me Sticky IS up to date.

    For you to "expect" a parser that we don't even want here to be up to date is also expecting a lot. We don't want it here, we don't EVER recommend it's usage. It cannot be brought up to date because we don't have the capability or the rights here to do that.

    Trend Micro owns the program, if you want a parser for THEIR program then you need to personally contact Trend Micro but WE don't want it here so YOU call Trend Micro ask them for one for yourself.

    As I stated above I have no clue what has been done to this brand new machine and for me to make any more suggestions would be 100% against my better judgement. I am sorry.

  2. #2
    Join Date
    Feb 2007
    Location
    Pennsylvania
    Age
    69
    Posts
    33
    Microsofts regedit.exe i Dont use registry cleaners i just edit the registry directly....I do NOT reccomend people do this...I have been trained to use registry editor !!
    Windows XP Pro w/SP3
    AMD Phenom II X4 955 B.E. (C2) OC'd to 3.8Ghz
    ASUS M4N82 Deluxe 980a SLI Mobo
    EVGA GeForce GTX 580 1536MB
    Corsair CM2X2048-8500C5D Dual Channel
    SATA WD 300GB Velociraptor
    WD 1TB Caviar Black
    LG GH22LS30 CD/DVD Burner
    PC Power & Cooling Silencer 750W
    ViewSonic G90FB 19" CRT Monitor
    Harmon Kardon Speakers (3)
    Coolermaster ATCS 840 Full Tower
    3x230mm, 1x120mm, Optional: 3x Scythe S-Flex SFF21G 120mm
    ZALMAN CNPS 10X Extreme CPU Cooler
    Steelseries 6GV2 Keyboard

  3. #3
    Join Date
    Feb 2007
    Location
    Pennsylvania
    Age
    69
    Posts
    33
    Ok here is the next LOCO log I have bolded the things I think should be removed....I've googled them to no help....

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 11:13:52 PM, on 7/29/2010
    Platform: Windows 7 (WinNT 6.00.3504)
    MSIE: Internet Explorer v8.00 (8.00.7600.16385)
    Boot mode: Normal

    Running processes:
    C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
    C:\Users\James\Desktop\HijackThis.exe
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    C:\Windows\SysWOW64\NOTEPAD.EXE

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    F2 - REG:system.ini: UserInit=userinit.exe
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
    O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762# # (Bonjour Service) - Apple Computer, Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
    O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
    O23 - Service: Updater Service - Acer - C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\SysWOW64\ZoneLabs\vsmon.exe
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

    --
    End of file - 5416 bytes


    Ok now I need expert help....I WANT to remove the bolded entries from his system...but googling them gives no positive results so I'll ask here. He uses no Apple Products or services and has no Windows Live account and doesnt want one> Help on the bolded items would be appreciated

    IF they are not necessary to Win 7 OS then I will remove them...But sincce I can't find any reliable info on the bolded items....I've posted them here. Please remember...he only has a ONE Mb/s connection shared between two comps....my "mission" is to remove anything that EVER tries to use any of his connection bandwidth.

    EDIT: Ok, I just found out that for HIS particular system Windows Live Writer is useless...so that can go...all that leaves is the bonjour thingy...he uses no Apple or Mac devices and will never use them or iTunes....so...axe bonjour also?

    DISCLAIMER:

    This is ONLY posted for a particular person with a particular comp with particular needs...DO NOT attempt to do the things I have done. Ask a professional on this site FIRST.
    Last edited by Ghot; 07-29-2010 at 11:14 PM.
    Windows XP Pro w/SP3
    AMD Phenom II X4 955 B.E. (C2) OC'd to 3.8Ghz
    ASUS M4N82 Deluxe 980a SLI Mobo
    EVGA GeForce GTX 580 1536MB
    Corsair CM2X2048-8500C5D Dual Channel
    SATA WD 300GB Velociraptor
    WD 1TB Caviar Black
    LG GH22LS30 CD/DVD Burner
    PC Power & Cooling Silencer 750W
    ViewSonic G90FB 19" CRT Monitor
    Harmon Kardon Speakers (3)
    Coolermaster ATCS 840 Full Tower
    3x230mm, 1x120mm, Optional: 3x Scythe S-Flex SFF21G 120mm
    ZALMAN CNPS 10X Extreme CPU Cooler
    Steelseries 6GV2 Keyboard

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •